Path traversal in starlette - CVE-2023-29159

 

Path traversal in starlette - CVE-2023-29159

Published: May 30, 2023


Vulnerability identifier: #VU76618
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-29159
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences. A remote attacker can send a specially crafted HTTP request and read arbitrary files on the system.


Affected software

starlette
Debian Linux
starlette (Debian package)
IBM Cloud Pak for Watson AIOps
IBM Cloud Pak for Business Automation
IBM Business Automation Workflow

How to mitigate CVE-2023-29159

Install update from vendor's website.

starlette - update to 0.27.0
starlette (Debian package) - addressed in versions 0.26.1-1+deb12u1, 0.46.1-3+deb13u2
IBM Cloud Pak for Watson AIOps - update to 4.1.1
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.29, 23.0.2.1
IBM Business Automation Workflow - update to 23.0.2 IF001

External References

Related Security Bulletins